SecureDoc: Removable Media Container Encryption (RMCE)
What happens to an encrypted USB drive when the person who knew the password leaves? WinMagic SecureDoc™ RMCE replaces shared passwords with enterprise key management, so authorized users on managed endpoints open encrypted containers automatically and departing employees lose access the moment their key is revoked. The brochure covers dual drive letters, Disc Access Control policies, executable quarantine, and secure sharing with external partners. Download the brochure to see how it works.
How does SecureDoc RMCE protect data on USB drives without using passwords?
SecureDoc RMCE reimagines removable media security by replacing passwords with enterprise key management.
On managed Windows or macOS endpoints, users access encrypted USB drives and external media automatically:
- No password prompts
- No shared credentials
- No helpdesk resets for forgotten passwords
Here’s how it works in practice:
- Users create an AES 256-bit encrypted container (up to 4 TB) on a USB drive, external hard drive, network share, or CD/DVD.
- When the media is inserted into a managed endpoint, it mounts with two drive letters (Windows): one for the encrypted container and one for any allowed unencrypted space.
- Group-based cryptographic keys unlock the encrypted container automatically in the background, so users just open File Explorer and work with files as usual.
Because keys—not passwords—control access, IT can:
- Assign company-wide, group, or personal keys per profile
- Revoke a single user’s key instantly when they leave, without changing any passwords
- Maintain long-term recoverability using human-readable key labels that link keys to users, departments, or groups
This approach reduces operational risk, removes the need for shared passwords, and keeps encrypted media recoverable even years later.
Can we still share encrypted USB data with external partners and unmanaged devices?
Yes, SecureDoc RMCE is designed to support secure sharing beyond your managed environment.
When you prepare a removable drive for external use, RMCE can embed a Media Viewer and Key File directly on the media. For recipients on unmanaged Windows or macOS devices:
- They insert the USB drive or other media.
- They use the built-in Media Viewer to open the encrypted container.
- They authenticate with a single password—no SecureDoc installation is required.
If that password is lost, the user can perform a Challenge Response recovery with an administrator to restore access, avoiding permanent data loss.
This model lets you:
- Share sensitive data securely with external partners, contractors, courts, or agencies
- Keep your internal users on passwordless, key-based access on managed endpoints
- Provide a straightforward password-based experience only for unmanaged recipients
In short, internal users benefit from automatic key unlocking, while external users get a simple, self-contained way to open encrypted content on any compatible device.
What management and compliance controls does SecureDoc RMCE provide for IT and security teams?
SecureDoc RMCE is centrally managed through SecureDoc Enterprise Server (SES), giving IT and security teams detailed control over how removable media is used and audited.
Key management and policy controls include:
- Group-based keys & key rings: Company-wide, group, and user keys can be assigned per profile so multiple users or AD groups can unlock the same container without sharing passwords.
- Key labeling: Human-readable labels tie keys to users, departments, or groups, making it easy to identify the right key even years later and ensuring long-term data recoverability.
- Granular policy control: Policies are applied at the device level, with user and key associations managed via SES. You can configure behavior per specific user on a specific device.
- Disc Access Control (DAC): Enforce encryption on all writes and define how unencrypted space is handled (no access, read-only, or read-only if not encrypted).
- Partial encryption with dual drive letters: RMCE can split media into encrypted and unencrypted areas, each with its own drive letter and policy set.
- Trusted Device Allow List: Only pre-approved drives are allowed to connect; unauthorized devices are blocked before any content is accessed.
- Executable quarantine: Executable files on unencrypted space are automatically renamed to
.quarantine, preventing them from running on managed endpoints while remaining recoverable by an admin.
For compliance and visibility, RMCE provides:
- File activity logging: Names of all files written to both encrypted containers and unencrypted space on managed devices are logged.
- Centralized audit trail: Logs are transferred to the SES console, supporting audits for regulations such as HIPAA, GDPR, and PCI DSS.
Together, these capabilities help IT teams reshape how removable media is controlled, monitored, and governed across the organization.
SecureDoc: Removable Media Container Encryption (RMCE)
published by BlueTeamAssess LLC
I founded BlueTeamAssess LLC to develop and offer actionable and cost effective security solutions to SMBs.
BlueTeamAssess LLC is a veteran-owned Cybersecurity Consulting business based in Onslow County, NC.
My company wants to be the trusted advisor to small businesses for cybersecurity and related information technology needs. We will help you meet compliance requirements for HIPAA, PCI, NC cybersecurity requirements for financial advisors, and NIST 800-171 and CMMC cybersecurity requirements for providing goods and services through DOD contracts.
We help small businesses understand cybersecurity threats and their vulnerability to those threats. We offer affordable products and services to protect their business and their livelihood from those threats.
We use the SAINT Security Suite and its family of assessment products to provide cybersecurity services that assess your exposure to the many threats that can impact your business. And we help you meet compliance requirements for NIST 800-171 cybersecurity requirements for providing goods and services through DOD contracts as well as for HIPAA, PCI, the NC data breach protection law and NC cybersecurity requirements for financial advisors.
We use the CyberSecurity Assessment Tool from QS Solutions to assess the security posture of your Microsoft 365 deployment and help bring your risk score to acceptable levels through our remediation services.
We will help you reduce SPAM, secure your email and defend against ransomware. To help do this, we offer a number of solutions scalable for small business budgets and environments. These include:
- Microsoft 365 email and office software and its extensive security features and advanced threat protection.
- Fortinet security solutions that provide a Security Fabric that knits together protection for your endpoints and servers, your firewalls, your wireless network, security analytics and many other services that protect your organization technology from today’s advanced threats whether the workers are working in the office or remotely from home.
- A backup and recovery solution from Acronis to protect your critical customer and business data when the next storm or other disaster impacts your business.
You can trust BlueTeamAssess LLC be the trusted advisor to small businesses for cybersecurity and related information technology needs.